CVE-2025-31324
CRITICAL KEV RANSOMWARE NUCLEISAP NetWeaver Visual Composer Metadata Uploader - Deserialization
Title source: nucleiDescription
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Exploits (22)
nomisec
WORKING POC
20 stars
by antichainalysis · remote
https://github.com/antichainalysis/sap-netweaver-0day-CVE-2025-31324
nomisec
SCANNER
12 stars
by Onapsis · poc
https://github.com/Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
nomisec
SCANNER
8 stars
by Onapsis · poc
https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment
github
WRITEUP
7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-31324.md
nomisec
WORKING POC
5 stars
by rf-peixoto · remote
https://github.com/rf-peixoto/sap_netweaver_cve-2025-31324-
nomisec
SCANNER
1 stars
by nairuzabulhul · infoleak
https://github.com/nairuzabulhul/nuclei-template-cve-2025-31324-check
nomisec
WORKING POC
1 stars
by nullcult · remote
https://github.com/nullcult/CVE-2025-31324-File-Upload
nomisec
WORKING POC
1 stars
by abrewer251 · remote
https://github.com/abrewer251/CVE-2025-31324_PoC_SAP
nomisec
WORKING POC
by harshitvarma05 · poc
https://github.com/harshitvarma05/CVE-2025-31324-Exploits
nomisec
SCANNER
by BlueOWL-overlord · remote
https://github.com/BlueOWL-overlord/Burp_CVE-2025-31324
Nuclei Templates (1)
SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
CRITICALVERIFIEDby iamnoooob,rootxharsh,parthmalhotra,pdresearch
Shodan:
html:"SAP NetWeaver Application Server Java"
References (6)
Scores
CVSS v3
10.0
EPSS
0.3458
EPSS Percentile
97.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2025-04-29
VulnCheck KEV
2025-04-22
ENISA EUVD
EUVD-2025-11987
Ransomware Use
Confirmed
CWE
CWE-434
Status
published
Products (1)
sap/netweaver
7.50
Published
Apr 24, 2025
KEV Added
Apr 29, 2025
Tracked Since
Feb 18, 2026